Add "Security" check: project has published a CVE
Open
area/core
new check
on hold
- Dominant language
- TypeScript
- Stars
- 149
- Forks
- 106
- Avg merge
- 15h 4m
- Merged PRs (30d)
- 4
Description
We should check that a project has published a CVE
https://github.com/containerd/containerd/security/advisories
It shouldn't have a ton of weight but it's a good practice for projects to do so
Contributor guide
Research direction
Start by reviewing the linked containerd security advisories and the repository's existing project-health checks. Determine how a published CVE should be detected and weighted, then verify that the new Security check reports projects with and without a published CVE as intended.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github, typescript
- Domain
- security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100